Secure messaging in Vommet
Your private messages in Vommet are end-to-end encrypted (not every chat is): nobody but you and the people you're talking to can read them, not even the people who run your server. That's much stronger privacy than most chat apps give you. It also means you hold the keys, and keeping them safe is your job. This page explains how, in plain language.
1. Only you hold the keys
When you send a private message, Vommet locks it on your device before it leaves. Your server passes the locked message along, but it can't open it. Only the devices of the people in the chat have the keys to unlock it.
The price of that privacy is that nobody can rescue you if you lose your keys. Not us, not your server's admins. Vommet will help you keep them safe, but in the end it's up to you.
Which chats are encrypted?
Not every chat is. Encryption is set per room:
- Direct messages you start in Vommet are encrypted from the first message.
- Private rooms are usually encrypted, but whoever made the room decides.
- Many public rooms are not encrypted, so anyone who joins can read their history. Treat them like a public forum.
- Older chats, or ones started in other apps, may not be encrypted, even direct messages.
- Bridged chats (rooms connected to Discord, Telegram and similar) pass through a bridge that has to read your messages to deliver them to the other app, even if the Matrix side is encrypted.
To check a room, look at the message box: it says "Send an encrypted message" with a padlock, or "Send an unencrypted message" with a crossed-out padlock. A room that isn't encrypted also shows a small crossed-out padlock right after its name at the top, and so does a call in that room. Tap it to see what it means. A room can be switched from unencrypted to encrypted, but never back.
In direct messages, the spot after the person's name shows the most important thing about them: a green shield if you've verified them, a red shield if their identity changed, and an amber crossed-out padlock in the rare case that the chat isn't encrypted.
What encryption doesn't hide: your server still knows which rooms you're in, who you message and when. Encryption protects what you say, not the fact that you said something.
2. Your password and your recovery key are different
Your password
Gets you into your account. Your server checks it when you sign in. If you forget it, your server can usually help you reset it.
Your recovery key
Unlocks your private messages. Your server never sees it. If you lose it (and all your devices), nobody can reset it for you.
Resetting your password does not bring back messages you can't unlock. Use a recovery key or recovery password that is different from your account password: if they're the same, anyone who learns your password can also read your messages.
3. Saving your recovery key
Treat it like your house key
Together with your account password, your recovery key lets someone read your whole message history and pretend to be you. Store it somewhere encrypted that only you can open.
When you set up secure messaging, Vommet offers a few ways to keep your key. In order of what we recommend:
- An end-to-end encrypted password manager. The best choice for almost everyone. It's encrypted, it's backed up, it's on all your devices, and you won't lose it the way you lose a scrap of paper. See which password manager.
- A memorable phrase. Vommet picks 6 easy words for you. Easy to remember, but save it in your password manager too: people forget things they rarely use.
- Your own recovery password. Only if it's long and you don't use it anywhere else. A password you only use here is exactly the kind people forget, so save it in your password manager as well.
Don't keep it in these
- A screenshot or photo (photos sync to the cloud and get shared by accident)
- A printout or a file saved to print (paper and print queues aren't encrypted)
- A note on your phone, an email to yourself, or a document in Google Docs, OneDrive or iCloud Drive
- A message to a friend, or to yourself in a chat app
If you really must write your phrase down, treat the paper like cash: anyone who finds it can use it, so lock it away.
Vommet asks you to type your key or phrase back before it finishes setting up, to make sure you really have it. Now and then it will ask again, so you find out early if you've lost it rather than on the day you need it.
4. Which password manager?
A password manager is an app that remembers your passwords for you, locked behind one main password or your fingerprint. For your recovery key, it has to be end-to-end encrypted: the company that makes it must not be able to read what you store. Many people assume the one built into their phone or browser is. Often it isn't.
Recommended
- Bitwarden: free, open source, works on every phone and computer. The Vommet developers recommend it if you don't have one yet.
- Apple Passwords / iCloud Keychain: on iPhone, iPad and Mac.
- Proton Pass: free plan available.
- 1Password: paid.
- Firefox, if you sync with a Mozilla account.
- KeePassXC / KeePassDX: an encrypted file on your own devices. You're in charge of backing it up.
Check your settings
- Google Password Manager (Android, Chrome): not end-to-end encrypted unless you turn on "on-device encryption" in its settings. By default, Google holds the keys.
- Samsung Pass: can sync end-to-end encrypted on newer Galaxy phones, but check that it's switched on.
Not recommended
- Microsoft Edge saved passwords: we couldn't confirm they're end-to-end encrypted.
- LastPass: stored password vaults were stolen in a 2022 breach.
- Notes apps, documents, email and chat (not password managers at all).
If Vommet sees that your phone saves passwords to Google, it will remind you of this when you save your key.
Password managers change their features. This list was last checked in October 2026. If you know it's out of date, please tell us.
5. Signing in on a new device
Each phone or computer you sign in on is a separate device with its own keys. When you sign in somewhere new, Vommet asks you to approve it:
- From a device you already use: open Vommet there and tap Approve, then check that the emoji match on both screens.
- With your recovery key or phrase, if you have no other device signed in.
6. When would you lose your messages?
- ✓You lose your phone, but your laptop is still signed in.
Fine. Approve your new phone from your laptop. - ✓You lose every device, but you have your recovery key.
Fine. Sign in anywhere, enter your key, and your history comes back. - ✕You're signed out everywhere and you don't have your recovery key.
Your old private messages are gone for good. Nobody can recover them.
That last case is the only way to lose them, and your recovery key is what protects you from it. Signing out of one device, reinstalling the app or getting a new phone are all fine as long as you still have another approved device or your key.
7. Warnings about other people
Vommet also checks whether the people you message have secure messaging set up, because that's how it knows a device really belongs to them.
"We can't confirm this is really them"
The person hasn't verified their devices. Most of the time they just haven't set up secure messaging yet. But it also means Vommet can't tell their real devices apart from one added by someone impersonating them, for example someone who stole their password. Some of your messages may also not reach all of their devices.
What to do: you can still message them. Tap Let them know to send a friendly nudge with a link to this page. Before sharing anything sensitive, you can verify them.
"Their identity changed"
This one matters more. Their secure messaging was reset since you last talked. That happens when someone loses all their devices and their recovery key, but it's also exactly what it looks like when someone is impersonating them.
What to do: check with them another way, such as a call, in person, or a different app you already trust. Ask whether they reset their account. Don't share anything private until you're sure. If it was them, tap It was them. Or better, verify them.
Verifying someone
Open their profile and tap Verify. You'll both see a set of emoji. Compare them in person or on a call, not by text in the same chat. If they match, you're talking to the real person, and Vommet will warn you if that ever changes.
8. Never share your recovery key
Nobody needs your recovery key to help you. Not the Vommet developers, not your server's admins, not a friend helping you set up. Anyone who asks for it is trying to get into your messages.
If you paste something that looks like a recovery key into a message, Vommet will stop and ask before sending it.
If you think someone has seen your key, ask for help in #vommet:nether.im and we'll walk you through making a new one. A new key also gives you a new identity, so the people you talk to will see that your identity changed: tell them it was you.
Questions
Ask in #vommet:nether.im or open an issue.